<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T21:20:59.474927+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:56133</id>
    <title>ALSA-2026:56133 — Moderate: attr security update</title>
    <updated>2026-10-03T21:20:59.918113+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: attr, AlmaLinux:8: libattr, AlmaLinux:8: libattr-devel</p>
<p>The attr packages provide extended attributes, which can be used to store system objects like capabilities of executables and access control lists, as well as user objects.</p>
<p>Security Fix(es):</p>
<p>* attr: Symlink Traversal Privilege Escalation via getfattr and setfattr (CVE-2026-54371)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:56133"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1249</id>
    <title>certfr-2026-avi-1249 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-03T21:20:59.918198+00:00</updated>
    <content>certfr-2026-avi-1249</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1249"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-366750</id>
    <title>EUVD-2026-366750</title>
    <updated>2026-10-03T21:20:59.918220+00:00</updated>
    <content>EUVD-2026-366750</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-366750"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54371</id>
    <title>fkie_cve-2026-54371</title>
    <updated>2026-10-03T21:20:59.918233+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-54371"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hh95-r7mj-c9j5</id>
    <title>GHSA-hh95-r7mj-c9j5</title>
    <updated>2026-10-03T21:20:59.918257+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hh95-r7mj-c9j5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-54371</id>
    <title>msrc_CVE-2026-54371 — attr &lt; 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattr</title>
    <updated>2026-10-03T21:20:59.918274+00:00</updated>
    <content>msrc_CVE-2026-54371</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-54371"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2913</id>
    <title>OESA-2026-2913 — attr security update</title>
    <updated>2026-10-03T21:20:59.918290+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: attr</p>
<p>A set of tools for manipulating extended attributes on file system objects, in particular getfattr(1) and setfattr(1). An attr(1) command is also provided, which is largely compatible with the SGI IRIX tool of the same name.

Security Fix(es):</p>
<p>attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.(CVE-2026-54371)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2913"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11312-1</id>
    <title>openSUSE-SU-2026:11312-1 — acl-2.4.0-1.1 on GA media</title>
    <updated>2026-10-03T21:20:59.918314+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>acl-2.4.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11312-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:34889</id>
    <title>RHSA-2026:34889 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
    <updated>2026-10-03T21:20:59.918331+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>attr: attr: Symlink Traversal Privilege Escalation via getfattr and setfattr</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:34889"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:56133</id>
    <title>RLSA-2026:56133 — Moderate: attr security update</title>
    <updated>2026-10-03T21:20:59.918355+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: attr</p>
<p>The attr packages provide extended attributes, which can be used to store system objects like capabilities of executables and access control lists, as well as user objects.</p>
<p>Security Fix(es):</p>
<p>* attr: Symlink Traversal Privilege Escalation via getfattr and setfattr (CVE-2026-54371)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:56133"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23670-1</id>
    <title>SUSE-SU-2026:23670-1 — Security update for acl, attr</title>
    <updated>2026-10-03T21:20:59.918377+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for acl, attr</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23670-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54371</id>
    <title>UBUNTU-CVE-2026-54371</title>
    <updated>2026-10-03T21:20:59.918393+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: attr, Ubuntu:Pro:16.04:LTS: attr, Ubuntu:Pro:18.04:LTS: attr, Ubuntu:Pro:20.04:LTS: attr, Ubuntu:22.04:LTS: attr, Ubuntu:24.04:LTS: attr, Ubuntu:25.10: attr, Ubuntu:26.04:LTS: attr</p>
<p>attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54371"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2920</id>
    <title>WID-SEC-W-2026-2920 — Red Hat Enterprise Linux (attr): Schwachstelle ermöglicht Privilegieneskalation</title>
    <updated>2026-10-03T21:20:59.918423+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux (attr) ausnutzen, um seine Privilegien zu erhöhen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2920"/>
  </entry>
</feed>
